Category PS3 Jailbreaking       Thread starter PSXHAX       Start date Aug 16, 2017 at 9:14 AM       8,037       8            
As work began porting the PS3 WebKitSploit and PS3 Playground, @cakehonolulu let us know in the Shoutbox of a write-up he did recently Investigating the PS3 Browser on Github for PlayStation 3 developers. :thumbup:

Those interested can check out the article in it's entirety HERE, and to quote from it in part:

But how can we exploit PS3's WebKit engine then?

Well, that's a matter of time, you can look up on the Internet about old Webkit bugs and test if they work on the PS3, then you could craft an exploit from them. But what's the point of running unsigned code on the userland in the PS3 nowadays when Custom Firmwares are up on all the Scenes and Downgrading has become a very used technique in order to install a full-blown Custom Firmware on the PS3?

Well, there are a lot of people that can't afford a downgrader, or they don't know how to solder, or they fear that they will kill the PS3 by doing thoose things... There are a lot of reasons to research on newer PS3 models, but the first one is: Doing it for fun as past hackers did it.

Hey! Where's my TL;DR

Well, i'll resume this as much as I can: Motivated by some fellas that were porting PS4 WebKit exploits to PS3, found out that they can't work on the PS3 because Sony has (Again) failed to provide a good WebKit base by removing functionalities that are useful (In this case, TypedArrays) in the Webkit exploiting world.
PlayStation 3 Browser Investigation for PS3 Devs by Cakehonolulu.jpg
 

Comments

bombob

Lets work it out
Senior Member
Contributor
Verified
well its too bad things are gona take a lot more time for 4.81 OFW ps3 owners. I was all hyped
 

esc0rtd3w

Developer
Member
Contributor
this is amazing! Thanks dude! Keep that thing updated whenever possible, cause my brain is hurting enough already...lol :D

Question: If Flash 9 can handle TypedArrays or perhaps other apps, or even the PSN Store could emulate this functionality, wouldn't some of the TypedArray stuff be viable or am I just talking out of my :poop:

do you think we could leverage HTML5 to do TypedArrays?? Sorry so many questions :confused:
 

cakehonolulu

Developer
Member
Contributor
this is amazing! Thanks dude! Keep that thing updated whenever possible, cause my brain is hurting enough already...lol :D

Question: If Flash 9 can handle TypedArrays or perhaps other apps, or even the PSN Store could emulate this functionality, wouldn't some of the TypedArray stuff be viable or am I just talking out of my :poop:

do you think we could leverage HTML5 to do TypedArrays?? Sorry so many questions :confused:
Well, I'm not sure if PS3's Browser Flash applet can be exploited or not, but what i'm sure is that the PS4 exploits that are being ported, won't work.

If you could craft some sort of Array that resembles the one that is missing on the PS3's Webkit, then you could exploit the PS3 without any problems.
 

testingdis

Contributor
i used html5test.com to test the features the browser supports and noticed that it doesn't support much features.

esc0rtd3w looks as though he has found something here github/esc0rtd3w/ps3-playground/blob/master/test/index.html
but it just looks as if hes copy pasting CVE articles and doesn't actually know how to exploit it
 

esc0rtd3w

Developer
Member
Contributor
@testingdis i also used html5test.com and yes the PS3 browser is VERY limited.... actually was copying those CVE vulns so other people can test on their own. Our team already has working exploits for 4.81 that we are currently working on.

and yeah, you are right.... i do not know how to exploit it :rolleyes: please show us the way! haha
 
Recent Articles
PS4 IOCTL Nabber IDA 7.0-7.2 Script for IOCTL Requests by SocraticBliss
Proceeding his PS4 Module Dumper Payload and PS4 Kernel Fixup Script, PlayStation 4 developer @SocraticBliss (Twitter) added a PS4 IOCTL Nabber to his Github repository for use with the IDA...
Free Holiday Brush Pack Arrives for Concrete Genie on PlayStation 4
Christmas is still a few weeks away, but the festive folks at Pixelopus announced that a free Holiday Brush Design Pack is now available for Concrete Genie on PlayStation 4! 🎨🖌:santa: Here's the...
Sony CEO Confirms No Interest in Making Another Handheld Console
A few weeks back CEO Jim Ryan revealed Sony's plans to Transition to PS5, and in a recent interview with GameInformer.com he confirmed that PlayStation is also no longer interested in making...
Monster Hunter World: Iceborne x Horizon Zero Dawn: The Frozen Wilds PS4
Following the Monster Hunter: World PS4 Pro LE Bundle and Monster Hunter World: Iceborne Expansion, today Capcom announced that the gates to the Tundra Region have opened in Monster Hunter World...
Top